CVE-2026-98338: wifi: cfg80211: ibss: ref BSS entry for joined event
In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: ibss: ref BSS entry for joined event
When the IBSS is joined, we only record the BSSID/channel in the event and look up the BSS entry when processing it. However, that's racy, e.g. a new scan with NL80211SCANFLAGFLUSH can remove it, causing a warning in the event work:
!bss WARNING: net/wireless/ibss.c:37 at cfg80211ibssjoined+0x3d3/0x440 Workqueue: cfg80211 cfg80211eventwork cfg80211processwdevevents+0x39f/0x5b0 net/wireless/util.c:1144 cfg80211processrdevevents+0xa1/0x110 net/wireless/util.c:1179 cfg80211eventwork+0x2f/0x40 net/wireless/core.c:393
Do the lookup early (the driver is expected to only join an IBSS that has a BSS entry) and keep a reference to it.
Affected Software
Event History
Frequently Asked Questions
What conditions are required to trigger the issue?
A device must join an IBSS network, and a subsequent scan using NL80211_SCAN_FLAG_FLUSH must remove the associated BSS entry before the queued joined event is processed. The race then causes the event work to find no BSS entry and emit a kernel warning.
Which systems are most likely to be exposed?
Systems using Linux kernel Wi-Fi functionality with cfg80211 and participating in IBSS (ad-hoc) networks are relevant. The issue is specifically tied to IBSS join event handling rather than ordinary infrastructure-mode Wi-Fi operation.
How can I identify that the issue has occurred?
Kernel logs may contain a warning beginning with "!bss WARNING: net/wireless/ibss.c:37" and a stack trace involving __cfg80211_ibss_joined, cfg80211_process_wdev_events, and cfg80211_event_work.